Software-update: RouterOS 6.42

MikroTik heeft kort geleden RouterOS 6.42 uitgebracht. RouterOS is een besturingssysteem dat zich richt op het uitvoeren van routertaken, denk daarbij aan natuurlijk het routeren van netwerkverkeer, firewall, bandbreedtemanagement, aansturen van draadloze accesspoints, hotspotgateway en vpn-server. Het kan zowel op de hardware van MikroTik als op x86- of virtuele-machines zijn werk doen. Voor het gebruik is een licentie nodig, die bij de aankoop van MikroTik-hardware is inbegrepen. De lijst met veranderingen voor deze uitgave ziet er als volgt uit:

What's new in 6.42:
  • tile - improved system performance and stability ("/system routerboard upgrade" required);
  • w60g - increased distance for wAP 60G to 200+ meters;
  • bridge - added host aging timer for CRS3xx and Atheros hw-bridges;
  • bridge - added per-port forwarding options for broadcasts, unknown-multicasts and unknown-unicasts;
  • bridge - added per-port learning options;
  • bridge - added support for static hosts;
  • bridge - fixed "master-port" configuration conversion from pre-v6.41 RouterOS versions;
  • bridge - fixed bridge port interface parameter under "/interface bridge host print detail";
  • bridge - fixed false MAC address learning on hAP ac^2 and cAP ac devices;
  • bridge - fixed incorrect "fast-forward" enabling when ports were switched;
  • bridge - fixed MAC learning for VRRP interfaces on bridge;
  • bridge - fixed reliability on software bridges when used on devices without switch chip;
  • bridge - hide options for disabled bridge features in CLI;
  • bridge - show "hw" flags only on Ethernet interfaces and interface lists;
  • capsman - added "allow-signal-out-of-range" option for Access List entries;
  • capsman - added support for "interface-list" in Access List and Datapath entries;
  • capsman - improved CAPsMAN responsiveness with large amount of CAP interfaces;
  • capsman - log "signal-strength" when successfully connected to AP;
  • certificate - added PKCS#10 version check;
  • certificate - dropped DES support and added AES instead for SCEP;
  • certificate - dropped MD5 support and require SHA1 as minimum for SCEP;
  • certificate - fixed incorrect SCEP URL after an upgrade;
  • chr - added "open-vm-tools" on VMware installations;
  • chr - added "qemu-guest-agent" and "virtio-scsi" driver on KVM installations;
  • chr - added "xe-daemon" on Xen installations;
  • chr - added support for Amazon Elastic Network Adapter (ENA) driver;
  • chr - added support for booting from NVMe disks;
  • chr - added support for Hyper-V ballooning, guest quiescing, host-guest file transfer, integration services and static IP injection;
  • chr - added support for NIC hot-plug on VMware and Xen installations;
  • chr - fixed additional disk detaching on Xen installations;
  • chr - fixed interface matching by name on VMware installations;
  • chr - fixed interface naming order when adding more than 4 interfaces on VMware installations;
  • chr - fixed suspend on Xen installations;
  • chr - make additional disks visible under "/disk" on Xen installations;
  • chr - make Virtio disks visible under "/disk" on KVM installations;
  • chr - run startup scripts on the first boot on AWS and Google Cloud installations;
  • console - fixed "idpr-cmtp" protocol by changing its value from 39 to 38;
  • console - improved console stability after it has not been used for a long time;
  • crs1xx/2xx - added BPDU value for "ingress-vlan-translation" menu "protocol" option;
  • crs212 - fixed Ethernet boot when connected to boot server through CRS326 device;
  • crs326 - fixed known multicast flooding to the CPU;
  • crs3xx - added switch port "storm-rate" limiting options;
  • crs3xx - added “hw-offload” support for 802.3ad and “balance-xor” bonding;
  • detnet - fixed "detect-internet" feature unavailability if router had too long identity (introduced in v6.41);
  • dhcp - improved DHCP service reliability when it is configured on bridge interface;
  • dhcp - reduced resource usage of DHCP services;
  • dhcpv4-server - added "dns-none" option to "/ip dhcp-server network dns";
  • dhcpv6 - make sure that time is set before restoring bindings;
  • dhcpv6-client - added info exchange support;
  • dhcpv6-client - added possibility to specify options;
  • dhcpv6-client - added support for options 15 and 16;
  • dhcpv6-client - implement confirm after reboot;
  • dhcpv6-server - added DHCPv4 style user options;
  • dns - do not generate "Undo" messages on changes to dynamic servers;
  • email - set maximum number of sessions to 100;
  • fetch - added "http-content-type" option to allow setting MIME type of the data in free text form;
  • fetch - added "output" option for all modes in order to return result to file, variable or ignore it;
  • fetch - increased maximum number of sessions to 100;
  • filesystem - implemented additional system storage maintenance checks on ARM CPU based devices;
  • flashfig - properly apply configuration provided by Flashfig;
  • gps - improved NMEA sentence handling;
  • health - added log warning when switching between redundant power supplies;
  • health - fixed empty measurements on CRS328-24P-4S+RM;
  • hotspot - improved HTTPS matching in Walled Garden rules;
  • ike1 - display error message when peer requests "mode-config" when it is not configured;
  • ike1 - do not accept "mode-config" reply more than once;
  • ike1 - fixed wildcard policy lookup on responder;
  • ike2 - fixed framed IP address received from RADIUS server;
  • interface - improved interface configuration responsiveness;
  • ippool - added ability to specify comment;
  • ippool6 - added pool name to "no more addresses left" error message;
  • ipsec - fixed AES-CTR and AES-GCM support on RB1200;
  • ipsec - improved single tunnel hardware acceleration performance on MMIPS devices;
  • ipsec - properly detect interface for "mode-config" client IP address assignment;
  • ipv6 - fixed IPv6 behaviour when bridge port leaves bridge;
  • ipv6 - update IPv6 DNS from RA only when it is changed;
  • kidcontrol - initial work on "/ip kid-control" feature;
  • led - added "Dark Mode" support for wAP 60G;
  • led - added w60g alignment trigger;
  • led - fixed unused "link-act-led" LED trigger on RBLHG 2nD, RBLHG 2nD-XL and RBSXTsq 2nD;
  • led - removed unused "link-act-led" trigger for devices which does not use it;
  • lte - added initial support for Quectel LTE EP06-E;
  • Lte - added initial support for SIM7600 LTE modem interface;
  • lte - added support for the user and password authentication for wAP-LTE-kit-US (R11e-LTE-US);
  • lte - do not add DHCP client on LTE modems that doesn't use DHCP;
  • lte - fixed DHCP client adding for MF823 modem;
  • lte - fixed LTE band setting for SXT LTE;
  • mac-ping - fixed duplicate responses;
  • modem - added initial support for AC340U;
  • netinstall - fixed MMIPS RouterOS package description;
  • netinstall - sign Netinstall executable with an Extended Validation Code Signing Certificate;
  • netwatch - limit to read, write, test and reboot policies for Netwatch script execution;
  • poe - do not show "poe-out-current" on devices which can not determine it;
  • poe - hide PoE related properties on interfaces that does not provide power output;
  • ppp - added initial support for NETGEAR AC340U and ZyXEL WAH1604;
  • ppp - allow to override remote user PPP profile via "Mikrotik-Group";
  • quickset - fixed NAT if PPPoE client is used for Internet access;
  • quickset - properly detect IP address when one of the bridge modes is used;
  • quickset - properly detect LTE interface on startup;
  • quickset - show "G" flag for guest users;
  • quickset - use "/24" subnet for local network by default;
  • r11e-lte - improved LTE connection initialization process;
  • rb1100ahx4 - improved reliability on hardware encryption;
  • routerboard - added RouterBOOT "auto-upgrade" after RouterOS upgrade (extra reboot required);
  • routerboard - properly detect hAP ac^2 RAM size;
  • sniffer - fixed "/tool sniffer packet" results listed in incorrect order;
  • snmp - added "/caps-man interface print oid";
  • snmp - added "/interface w60g print oid";
  • snmp - added "board-name" OID;
  • snmp - improved request processing performance for wireless and CAP interfaces;
  • ssh - fixed SSH service becoming unavailable;
  • ssh - generate SSH keys only on the first connect attempt instead of the first boot;
  • ssh - improved key import error messages;
  • ssh - remove imported public SSH keys when their owner user is removed;
  • switch - hide "ingress-rate" and "egress-rate" for non-CRS3xx switches;
  • tile - added "aes-ctr" hardware acceleration support;
  • tr069-client - added "DownloadDiagnostics" and "UploadDiagnostics";
  • tr069-client - correctly return “TransferComplete” after vendor configuration file transfer;
  • tr069-client - fixed "/tool fetch" commands executed with ".alter" script;
  • tr069-client - fixed HTTPS authentication process;
  • traffic-flow - fixed IPv6 destination address value when IPFIX protocol is used;
  • upgrade - improved RouterOS upgrade process and restrict upgrade from RouterOS older than v5.16;
  • ups - improved communication between router and UPS;
  • ups - improved disconnect message handling between RouterOS and UPS;
  • userman - added support for ARM and MMIPS platform;
  • w60g - added "tx-power" setting (CLI only);
  • w60g - added RSSI information (CLI only);
  • w60g - added TX sector alignment information (CLI only);
  • watchdog - retry to send "autosupout.rif" file to an e-mail if initial delivery failed up to 3 times within 20 second interval;
  • Winbox - added "antenna" setting under GPS settings for MIPS platform devices;
  • winbox - added "crl-store" setting to certificate settings;
  • winbox - added "insert-queue-before" to DHCP server;
  • winbox - added "use-dn" setting in OSPF instance General menu;
  • winbox - added 160 MHz "channel-width" to wireless settings;
  • winbox - added DHCPv6 client info request type and updated statuses;
  • winbox - added missing protocol numbers to IPv4 and IPv6 firewall;
  • winbox - added possibility to delete SMS from inbox;
  • winbox - allow to comment new object without committing it;
  • Winbox - allow to open bridge host entry;
  • Winbox - fixed name for "out-bridge-list" parameter under bridge firewall rules;
  • winbox - fixed typo from "UPtime" to "Uptime";
  • winbox - fixed Winbox closing when viewing graph which does not contain any data;
  • winbox - improved stability when using trackpad scrolling in large lists;
  • winbox - made UDP local and remote TX size parameters optional in Bandwidth Test tool;
  • winbox - moved "ageing-time" setting from STP to General tab;
  • winbox - moved OSPF instance "routing-table" setting in OSPF instance General menu;
  • winbox - removed “VLAN” section from “Switch” menu for CRS3xx devices;
  • winbox - show Bridge Port PVID column by default;
  • winbox - show CQI in LTE info;
  • winbox - show dual SIM options only for RouterBOARDS which does have two SIM slots;
  • winbox - show only master CAP interfaces under CAPsMAN wireless scan tool;
  • winbox - use proper graph name for HDD graphs;
  • wireless - added "realm-raw" setting for "/interface wireless interworking-profiles" (CLI only);
  • wireless - added initial support for "nstreme-plus";
  • wireless - added support for "band=5ghz-n/ac";
  • wireless - added support for "interface-list" for Access List entries;
  • wireless - added support for legacy AR9485 chipset;
  • wireless - enable all chains by default on devices without external antennas after configuration reset;
  • wireless - fixed "wds-slave" channel selection when single frequency is specified;
  • wireless - fixed incompatibility with macOS clients;
  • wireless - fixed long "scan-list" entries not working for ARM based wireless interfaces;
  • wireless - fixed nv2 protocol on ARM platform SXTsq devices;
  • wireless - fixed RB911-5HnD low transmit power issue;
  • wireless - fixed RTS/CTS option for the ARM based wireless devices;
  • wireless - fixed wsAP wrong 5 GHz interface MAC address;
  • Wireless - improved compatibility with specific wireless AC standard clients;
  • wireless - improved Nv2 PtMP performance;
  • wireless - improved packet processing on ARM platform devices;
  • wireless - improved wireless performance on hAP ac^2 devices while USB is being used;
  • wireless - improved wireless scan functionality;

MikroTik logo

Versienummer 6.42
Releasestatus Final
Website MikroTik
Download https://mikrotik.com/download
Licentietype Betaald

Door Bart van Klaveren

Downloads en Best Buy Guide

21-04-2018 • 07:24

20

Submitter: mjonkers1989

Bron: MikroTik

Update-historie

Reacties (20)

20
20
15
1
0
4
Wijzig sortering
Afgelopen woensdag doorgevoerd op mijn wAP-ac en hAP-ac zonder issues. :O
Mijn CRS125 draait nog steeds op 6.41 6.40.5 vanwege het niet meer werken van IP-tv wanneer ik upgrade naar een nieuwere versie. Ben al een keer een dag bezig geweest om dit te repareren maar tot nu toe nog niet gelukt. Toen een Rollback gedaan. Nu ben ik naar een tweede crs125 aan het kijken om nieuwe configs op te testen zonder al teveel "downtime".

[Reactie gewijzigd door WeaZuL op 23 juli 2024 10:27]

Ha, ik ben zelf ook aan het kloten (6.41.3 op een hEX POE) om T-Mobile Glasvezel werkend te krijgen, internet is gelukt, IP-tv nog niet. Ik ben erg benieuwd welke provider jij hebt en hoe jij het dan werkend hebt op 6.41?
Ik heb o.a. een RB951G-2HnD i.c.m. KPN routed IPTV draaien op 6.42 zonder problemen. Is overigens omgebouwd naar de nieuwe bridges ipv. de gebruik maken van het switch menu.

Dus het is zeker werkend te krijgen, op KPN dan uit. Maar scheelt volgens mij niet heel erg van de andere providers.

[Reactie gewijzigd door XoReP op 23 juli 2024 10:27]

Heb je voor KPN nog instellingen moeten wijzigen om het werkend te krijgen?
Na de update bleef het werken, enkel heb ik daarna handmatig de switch config eruit gehaald en alles op de bridiges ingesteld zodat het conform de nieuwe methode is.
heb je een configuratie export?
Hier een opgeschoonde config snip (OSPF/Tunnel/extra VLAN's/andere niet relevante gedeeltes eruit gefilterd)


/interface bridge
add igmp-snooping=yes name=bridgeIPTV-LAN
add name=bridgeLAN vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment=WAN-Trunk
set [ find default-name=ether2 ] comment=LAN
set [ find default-name=ether3 ] comment=LAN
set [ find default-name=ether4 ] comment=IPTV
set [ find default-name=ether5 ] comment=IPTV
/interface vlan
add comment=WAN-IPTV interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan4 vlan-id=4
add comment=WAN-Internet interface=ether1 loop-protect-disable-time=0s loop-protect-send-interval=0s name=vlan6 vlan-id=6
/interface list
add name=WAN
add name=LAN
add name=ITV
/ip dhcp-client option
add code=60 name=option60-vendorclass value="'IPTV_RG'"
/ip dhcp-server option
add code=60 name=option60-vendorclass value="'IPTV_RG'"
add code=28 name=option28-broadcast value="'10.255.14.255'"
/ip dhcp-server option sets
add name=IPTV-LAN options=option60-vendorclass,option28-broadcast
/ip pool
add name=dhcpLAN ranges=10.255.11.100-10.255.11.199
add name=dhcpTV ranges=10.255.14.2-10.255.14.254
/ip dhcp-server
add address-pool=dhcpLAN authoritative=after-2sec-delay disabled=no interface=vlan11 lease-time=1w1d name=dhcpLAN
add address-pool=dhcpTV authoritative=after-2sec-delay dhcp-option-set=IPTV-LAN disabled=no interface=bridgeIPTV-LAN lease-time=1d name=dhcpTV
/ppp profile
add change-tcp-mss=no name=profileKPN
/interface pppoe-client
add add-default-route=yes comment=WAN-Internet default-route-distance=10 disabled=no interface=vlan6 keepalive-timeout=60 max-mru=1500 max-mtu=1500 name=pppoe-out1 profile=profileKPN use-peer-dns=yes user=xx-xx-xx-xx-xx-xx@internet
/interface bridge port
add bridge=bridgeLAN interface=wlan1
add bridge=bridgeLAN interface=ether2
add bridge=bridgeIPTV-LAN interface=ether4
add bridge=bridgeIPTV-LAN interface=ether5
add bridge=bridgeLAN interface=ether3
/interface list member
add interface=pppoe-out1 list=WAN
add interface=ether1 list=WAN
add interface=vlan4 list=WAN
add interface=vlan6 list=WAN
add interface=bridgeLAN list=LAN
add interface=bridgeIPTV-LAN list=LAN
add interface=bridgeIPTV-LAN list=ITV
/ip address
add address=10.255.11.1/24 interface=bridgeLAN network=10.255.11.0
add address=10.255.14.1/24 interface=bridgeIPTV-LAN network=10.255.14.0
/ip dhcp-client
add add-default-route=special-classless default-route-distance=254 dhcp-options=option60-vendorclass,hostname,clientid disabled=no interface=vlan4 use-peer-dns=no use-peer-ntp=no
/ip dhcp-server network
add address=10.255.14.0/24 dhcp-option-set=IPTV-LAN dns-server=213.75.116.129 gateway=10.255.14.1
/ip firewall filter
add action=accept chain=input comment="Accept ICMP" protocol=icmp
add action=accept chain=input comment="Accept established & related" connection-state=established
add action=accept chain=input comment="Accept igmp" in-interface=vlan4 protocol=igmp
add action=accept chain=input comment="Accept all for LAN" in-interface-list=LAN
add action=drop chain=input comment="Drop other" log-prefix="Dropped to router"
add action=fasttrack-connection chain=forward connection-state=established,related
add action=accept chain=forward comment="Accept established & related" connection-state=established,related
add action=drop chain=forward comment="Drop invalid" connection-state=invalid
add action=accept chain=forward comment="Accept LAN to WAN" connection-state="" out-interface-list=WAN in-interface-list=LAN
add action=accept chain=forward comment="Accept IPTV" in-interface=vlan4 log-prefix=IPTV out-interface-list=ITV
add action=drop chain=forward comment="Drop other" log=yes log-prefix="Drop other forwarding"
/ip firewall nat
add action=masquerade chain=srcnat dst-address=213.75.112.0/21 out-interface=vlan4
add action=masquerade chain=srcnat out-interface=pppoe-out1
/routing igmp-proxy
set quick-leave=yes
/routing igmp-proxy interface
add alternative-subnets=0.0.0.0/0 interface=vlan4 upstream=yes
add interface=bridgeIPTV-LAN

[Reactie gewijzigd door XoReP op 23 juli 2024 10:27]

Ik heb een foutje gemaakt, ik draai nog op de oude configuratie voor de switch configuratie wijziging. Dus ik ben ook benieuwd naar een werkende configuratie bijv. Icm KPN! _/-\o_
Dit is de derde opeenvolgende release met TILE improvements waarvoor een routerboot upgrade benodigd is. Jammer dat ze niet exact vertellen wat die improvements inhouden, ben vooral benieuwd of het mogelijke port-flapping issue nu verholpen zou moeten zijn.
Ja dat verbaast me ook elke keer.
Wel duidelijke uitleg over alle RouterOS updates, maar geen info over de firmware updates.
Wat is dat überhaupt TILE? :?
Een van de cpu architecturen die Mikrotik gebruikt, de CCR serie maakt bv gebruik van TILE processors waar een CRS125 gebruik maakt van MIPSBE. Zie de Mikrotik download pagina voor een overzicht van alle architecturen: https://mikrotik.com/download
TILE staat inderdaad voor de CPU serie die de CCR modellen van Mikrotik gebruik.
Ze kenmerken zich door multicore en met name gericht op netwerken en hardwarematige ipsec AES encryptie/decryptie. Deze CPU's doen het erg goed in snellere routers van Mikrotik.
Zie ook de info op deze pagina.
http://www.mellanox.com/page/multi_core_overview
Zoals je ziet is Tilera overgenomen door Mellanox.

Mikroltik gebruikt deze CPU's in de CCR1009, CCR1016, CCR1036 en de CCR1072 routers.
1009 staat voor 9 core CPU en 1036 voor 36 core CPU.

Ikzelf gebruik heel veel de CCR1009 modellen bij zakelijke klanten. Die hebben meer dan voldoende CPU power om alle firewall/routerings taken snel af te handelen. En ze hebben zowel SFP+ als SFP aansluitingen.
ik draai 6.42 met kpn.
en heb niks hoeven te veranderen.
Op wat voor mikrotik apparaat? Icm IP-tv?
ik heb zowel een rb2011 als rb3011 als een hex
Ik heb een rb3011 met kpn iptv. Werkt prima met versie 6.41
Ik gebruik een hEX PoE, direct aangesloten op xs4all glas.
Ik heb IPTV gebridged van het inkomende VLAN naar een fysieke ethernetpoort.
Werkt prima.
Je kan tegenwoordig ook met mikrotik gewoon routed iptv aan.
Ik doe ze standaard zo configureren.
Ondertussen is er alweer een nieuwe update, hoofdzakelijk vanwege een recent ontdenkte kwetsbaarheid. Wederom updaten dus en zaak om de pre-switch change config zo snel mogelijk om te gooien naar deze laatste versie 8)7

Op dit item kan niet meer gereageerd worden.